EventBot Trojan
EventBot is a newly observed trojan primarily targeting European banking, financial, and cryptocurrency applications.
Summary
EventBot is a newly observed trojan primarily targeting European banking, financial, and cryptocurrency applications.
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication, it is unclear how EventBot is delivered, although there are unconfirmed reports indicating it may be distributed through the Google Play Store disguised as utility applications.
When installed, EventBot will ask for full administration privileges before removing itself from the affected device's application launcher. It then uses Android's Accessibility features to collect system and user information, including location and installed application lists, before sending it to a command and control (C2) server. It will then monitor the user's web browser, SMS, and application inputs in order to extract credentials, as well as attempt to phish sensitive information from webpages the user visits. Any extracted credentials or information is then encrypted and sent to the C2 server
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect a trojan infection, NHS Digital advises that:
Please note that NCSC maintains guidance for securely configuring a wide range of end user device (EUD) platforms. For further details refer to their end user device security guidance pages. |
Indicators of compromise
Last edited: 29 June 2021 12:01 pm